NIST, ISO 27001 or CIS: which cybersecurity framework fits your SME?

Published on February 16, 20267 min read
A small-business owner standing before three signposts, choosing the cybersecurity framework that fits her company

An important client has just returned the signed contract with an unexpected attachment: a security questionnaire, and one line that sticks in Sophie B.'s throat — "Which framework do you rely on?" As the managing partner of an accounting firm, she protects highly sensitive payroll and bookkeeping data every day. But those three letters, NIST, ISO, CIS, mean nothing precise to her. Does she really have to choose? And which one?

Choosing a cybersecurity framework without climbing the wrong mountain

Let's start with the word that intimidates. A cybersecurity framework is neither a piece of software nor a certificate: it is a map. An organised list of good practices that tells you what to look at, and in what order, to protect your business. Nothing more. You can use it as a compass without ever aiming for an official stamp — and you don't need to be an IT specialist to benefit from it.

Three names come up almost every time. The good news: they don't compete with each other. They answer three different needs.

NIST CSF 2.0 — the compass for understanding

NIST CSF 2.0 (the Cybersecurity Framework published by the US standards agency NIST) is the most educational of the three. It sorts all of security into six simple functions: Govern, Identify, Protect, Detect, Respond, Recover. In other words: who decides, what you own, how you protect yourself, how you spot a problem, how you react, how you get back on your feet. It is voluntary, flexible, and readable without a technical background. For Sophie B., it is the ideal tool to lay out "where do we actually stand?" without drowning in detail.

ISO/IEC 27001:2022 — the language of large clients

ISO/IEC 27001:2022 is an international standard that describes how to set up an information security management system (ISMS) — plainly, a durable way to steer security, not just a one-off list of measures. Its distinctive feature: it can lead to a certification recognised everywhere, issued by an independent body. It is the reference that large groups and auditors speak. It calls for a long-term commitment and cannot be improvised in a week. But even without aiming for the certificate, it serves as a useful benchmark: "are we covering what this standard considers important?"

CIS Controls — the toolbox that acts fast

The CIS Controls (published by the Center for Internet Security, a non-profit organisation) are the most concrete of the three. They are a prioritised list of measures, from the most useful to the most detailed, with — good news — a first group designed for small structures. You begin with the actions that reduce risk the most: knowing what you own, protecting access, backing up properly. For an SME with no in-house IT specialist, this is often the best starting point, even before talking about a standard or a certificate.

And for a services SME, concretely?

An accounting firm like Sophie B.'s has no internal IT department and handles extremely sensitive data. In this situation, the most realistic path looks like this: start with CIS-style priority actions to cut risk quickly, use NIST CSF 2.0 as a map to organise your thinking and answer clients, and keep ISO 27001 as a medium-term goal — for the day a client makes it a condition. What never changes: Swiss law remains the baseline reference, whatever framework you choose.

What to take away

Three ideas to keep in mind if you are in Sophie B.'s shoes.

  • A framework is not an exam, it is a map. None of the three "certifies" that you are secure. They show you the path; you are the one who walks it. Cyber Passport puts it the same way: we structure a self-assessment, we don't issue a label.
  • You don't have to pick "the right one" once and for all. The three combine very well: CIS to act fast, NIST CSF to organise and talk "posture", ISO 27001 for the day a client requires it. Many Swiss SMEs start with CIS actions and keep ISO as a horizon.
  • In Switzerland, the first framework is neither American nor ISO: it is the law. The nFADP (the new Federal Act on Data Protection, in force since September 2023) expects security "appropriate" to the data you hold. For an accounting firm, that is compass number one. The EU GDPR only comes on top if you process data on people in the European Union.

Steps to put in place this week

1. Ask "why" before "which one"

Before comparing acronyms, write in one sentence why the question is coming up. A client auditing you? An nFADP concern about the data you keep? Simply the wish to sleep soundly? The answer points you to a framework far better than a comparison table. A "reassure a client" need leans towards ISO 27001 vocabulary; a "get organised" need leans towards NIST CSF; an "act right now" need leans towards CIS.

2. Do a first pass over the measures that matter most

Without laying out a full action plan, give yourself half an hour to mentally tick off the fundamentals, in the spirit of the first CIS measures. Do you know which tools and accounts actually exist in your firm? Is multi-factor authentication (a second proof on top of the password, for example a code received on your phone) active everywhere it matters? Have your backups already been tested by restoring them? These are also the steps highlighted by the NCSC (the National Cyber Security Centre, Switzerland's reference for SMEs): start with the concrete rather than the theory. Three solid "yes" answers are worth more than a standard on display.

3. Learn to speak the same language as your clients

When a client asks about "your framework", what they mainly want is reassurance. Note, in their own terms, what you already do: access control, endpoint protection, incident handling. NIST CSF 2.0 provides a free, readable vocabulary for exactly this; ISO 27001 serves as a benchmark to check nothing important is missing. You don't need a certificate to answer honestly — you need a clear picture of where you stand.

Where do you really stand?

Choosing a cybersecurity framework is less a question of "which one" than of "where am I, and against which requirements?". That is exactly the job of a multi-framework self-assessment: it looks at your organisation through several frameworks at once — the nFADP, ISO 27001, NIST CSF — and shows you, question by question, what is solid and what still rests on trust.

Cyber Passport certifies nothing and promises no compliance: the platform produces a structured self-assessment, shareable with a client or an auditor, that turns those three intimidating letters into concrete decisions. The related blueprint then helps you prioritise — what, who, how much effort — without jargon.

That is often the real first step, and the most reassuring one: it is not about choosing the right mountain on the first try, but about knowing which slope you already stand on, and which path climbs fastest. The framework will follow, almost on its own.

Topics

  • cybersecurity framework
  • NIST CSF 2.0
  • ISO 27001
  • CIS Controls
  • SME
  • compliance

Read next